<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: mjmas</title><link>https://news.ycombinator.com/user?id=mjmas</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 25 May 2026 00:28:29 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=mjmas" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by mjmas in "FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack"]]></title><description><![CDATA[
<p>> The attack suggests a hacker compromised some portion of BasedApparel.com</p>
]]></description><pubDate>Sat, 23 May 2026 01:03:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48243480</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=48243480</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48243480</guid></item><item><title><![CDATA[New comment by mjmas in "Why We've Filed a Referendum"]]></title><description><![CDATA[
<p>> That's... their choice, of course, but doesn't seem logical to me.<p>Wouldn't the question be more simply, Do you want your power bills to go up for the same power used?<p>And the nuclear accidents that have happend have mostly been overblown (apart from Chernobyl).</p>
]]></description><pubDate>Sat, 23 May 2026 00:27:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48243233</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=48243233</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48243233</guid></item><item><title><![CDATA[New comment by mjmas in "Mozilla to UK regulators: VPNs are essential privacy and security tools"]]></title><description><![CDATA[
<p>The very same office of the eSafety commissioner that is enforcing age verification for social media.<p><a href="https://www.esafety.gov.au/newsroom/blogs/social-media-minimum-age-compliance-report" rel="nofollow">https://www.esafety.gov.au/newsroom/blogs/social-media-minim...</a></p>
]]></description><pubDate>Sun, 17 May 2026 08:45:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48167132</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=48167132</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48167132</guid></item><item><title><![CDATA[New comment by mjmas in "Tell NYT, Atlantic, USA Today to keep Wayback Machine"]]></title><description><![CDATA[
<p>Is there a difference between that and User-agent: ia_archiver ?</p>
]]></description><pubDate>Wed, 13 May 2026 10:41:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48120188</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=48120188</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48120188</guid></item><item><title><![CDATA[New comment by mjmas in "Stop MitM on the first SSH connection, on any VPS or cloud provider"]]></title><description><![CDATA[
<p>It does note that it only protects against an attacker "who learns the cloud-init user-data at any point <i>after</i> the script terminates".<p>If the attacker can get the cloud-init user-data while the script is still running (in the time between sending the cloud-config.yaml and connecting with SSH to the machine) that would still allow MitM, but would require more effort on the attacker's part to leak the cloud-init data.<p>The point of the script was that leaking the cloud-init data after the script has completed is harmless.</p>
]]></description><pubDate>Mon, 11 May 2026 06:03:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48091507</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=48091507</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48091507</guid></item><item><title><![CDATA[New comment by mjmas in "The locals don't know"]]></title><description><![CDATA[
<p>OT, but I didn't know that .com allowed domains with a double-dash.</p>
]]></description><pubDate>Mon, 11 May 2026 05:45:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48091412</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=48091412</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48091412</guid></item><item><title><![CDATA[New comment by mjmas in "CVE-2026-31431: Copy Fail vs. rootless containers"]]></title><description><![CDATA[
<p>Though this won't work for some kernels:<p>If algif_aead was a builtin module, it needs to be disabled by adding 
  initcall_blacklist=algif_aead_init
to the boot cmdline.<p>However initcall_blacklist requires the kernel to be built with CONFIG_KALLSYMS.</p>
]]></description><pubDate>Tue, 05 May 2026 12:58:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=48021938</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=48021938</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48021938</guid></item><item><title><![CDATA[New comment by mjmas in "CVE-2026-31431: Copy Fail vs. rootless containers"]]></title><description><![CDATA[
<p>Having write access on anything you can read should be enough if libraries or binaries are shared (read-only) between the host and container.</p>
]]></description><pubDate>Tue, 05 May 2026 12:41:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48021700</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=48021700</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48021700</guid></item><item><title><![CDATA[New comment by mjmas in "Kids can bypass some age checks with a drawn-on mustache"]]></title><description><![CDATA[
<p>> let them all go there and not bother normal people.<p>The normal state does include people with children.</p>
]]></description><pubDate>Tue, 05 May 2026 12:26:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48021539</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=48021539</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48021539</guid></item><item><title><![CDATA[New comment by mjmas in "Microsoft Edge stores all passwords in memory in clear text, even when unused"]]></title><description><![CDATA[
<p>Yes, but the pin uses the TPM which allows other things like only ever allowing a low number of guesses before requiring a reset of the pin (using a password or other mechanism)</p>
]]></description><pubDate>Tue, 05 May 2026 02:53:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48017563</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=48017563</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48017563</guid></item><item><title><![CDATA[New comment by mjmas in "I don't want your PRs anymore"]]></title><description><![CDATA[
<p>Do you accept bug reports that just say "it doesn't work" or do you require reproducibility?</p>
]]></description><pubDate>Tue, 21 Apr 2026 21:55:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=47855061</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=47855061</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47855061</guid></item><item><title><![CDATA[New comment by mjmas in "It is incorrect to "normalize" // in HTTP URL paths"]]></title><description><![CDATA[
<p>> And at least according to this, the default setting is off<p>It appears to not default to off on my install (AlmaLinux 10).<p>I just tested now. Cloudflare normalises ../ and ./ paths and then the nginx proxy appears to normalise // to /:<p>nginx log:<p><pre><code>  1234:: - - [18/Apr/2026:12:59:05 +0000] "GET //test//doubleslash/url HTTP/1.1" 404 158 "-" "curl/8.19.0" "1234::"
</code></pre>
lighttpd log:<p><pre><code>  1234:: - - [18/Apr/2026:12:59:04 +0000] "GET /test/doubleslash/url HTTP/1.0" 404 158 "-" "curl/8.19.0"</code></pre></p>
]]></description><pubDate>Sat, 18 Apr 2026 13:04:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=47815595</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=47815595</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47815595</guid></item><item><title><![CDATA[New comment by mjmas in "It is incorrect to "normalize" // in HTTP URL paths"]]></title><description><![CDATA[
<p>Agreed. Reading through the RFC it certainly appears to support the blog article.<p>And looking around I found this SO answer noting nothing in the RFC:<p><a href="https://stackoverflow.com/a/24661288" rel="nofollow">https://stackoverflow.com/a/24661288</a></p>
]]></description><pubDate>Sat, 18 Apr 2026 12:48:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=47815509</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=47815509</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47815509</guid></item><item><title><![CDATA[New comment by mjmas in "It is incorrect to "normalize" // in HTTP URL paths"]]></title><description><![CDATA[
<p>And there are different rules for the email in the envelope and the message. One allows the user part of the email to contain spaces and the other doesn't.</p>
]]></description><pubDate>Sat, 18 Apr 2026 12:43:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=47815479</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=47815479</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47815479</guid></item><item><title><![CDATA[New comment by mjmas in "All 12 moonwalkers had "lunar hay fever" from dust smelling like gunpowder (2018)"]]></title><description><![CDATA[
<p>See: Polio<p><a href="https://en.wikipedia.org/wiki/History_of_polio" rel="nofollow">https://en.wikipedia.org/wiki/History_of_polio</a><p>> [...] Better hygiene meant that infants and young children had fewer opportunities to encounter and develop immunity to polio. Exposure to poliovirus was therefore delayed until late childhood or adult life, when it was more likely to take the paralytic form.[22]</p>
]]></description><pubDate>Sat, 18 Apr 2026 00:55:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=47812243</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=47812243</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47812243</guid></item><item><title><![CDATA[New comment by mjmas in "A Python Interpreter Written in Python"]]></title><description><![CDATA[
<p>> technically a python subset<p>So it can just run under CPython? If so, then that isn't too misleading.</p>
]]></description><pubDate>Fri, 17 Apr 2026 10:15:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=47804334</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=47804334</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47804334</guid></item><item><title><![CDATA[New comment by mjmas in "The dangers of California's legislation to censor 3D printing"]]></title><description><![CDATA[
<p>> was a thing<p>Still a thing in Australia.</p>
]]></description><pubDate>Tue, 14 Apr 2026 21:53:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=47771980</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=47771980</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47771980</guid></item><item><title><![CDATA[New comment by mjmas in "CPU-Z and HWMonitor compromised"]]></title><description><![CDATA[
<p>> PHP-era<p>PHP-era is still today</p>
]]></description><pubDate>Sat, 11 Apr 2026 14:16:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=47730842</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=47730842</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47730842</guid></item><item><title><![CDATA[New comment by mjmas in "A compelling title that is cryptic enough to get you to take action on it"]]></title><description><![CDATA[
<p>A second reply that happened because the article reappeared on the front page.</p>
]]></description><pubDate>Sat, 11 Apr 2026 07:03:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=47728220</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=47728220</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47728220</guid></item><item><title><![CDATA[New comment by mjmas in "JSON formatter Chrome plugin now closed and injecting adware"]]></title><description><![CDATA[
<p>The author's response to one of the reviews:<p><a href="https://chromewebstore.google.com/review-reply/b4a787df-64e5-4834-ab80-361443bb3692" rel="nofollow">https://chromewebstore.google.com/review-reply/b4a787df-64e5...</a><p>> Give Freely is not spyware/adware or any kind of 'scam'. It's an optional donation appeal that asks you (if you happen to visit a retailer which happens to be a Give Freely partner) to click a button to donate <i>unclaimed</i> affiliate fees, with most of the money going to Code.org or another charity of your choice. I've met the Give Freely team and trust them. It does not collect any PII or browsing activity, and it doesn't overwrite other affiliate/voucher codes so it never costs you anything. If you find the donation popup too intrusive/annoying you can disable it forever in the extension options, or in the donation popup itself.<p>> Code.org is a good cause that's relevant to a lot of the same people who use this extension regularly, and clicking a Give Freely donate button is a genuinely free and anonymous way to show your support for both, if you want to. If you don't like it you can turn it off, or if it makes you more comfortable you can switch to JSON Formatter Classic, which has no Give Freely code and corresponds with the v0.8 branch in my archived json-formatter GitHub repo. Or try one of the many forks or alternatives available on the store.<p>> JSON Formatter Classic: <a href="https://chromewebstore.google.com/detail/json-formatter-classic/caacnjeoikecoeepknkbjdcaediamaej" rel="nofollow">https://chromewebstore.google.com/detail/json-formatter-clas...</a></p>
]]></description><pubDate>Sat, 11 Apr 2026 05:42:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=47727776</link><dc:creator>mjmas</dc:creator><comments>https://news.ycombinator.com/item?id=47727776</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47727776</guid></item></channel></rss>